Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-62130 2 Wordpress, Wpdiscover 2 Wordpress, Accordion Slider Gallery 2026-01-05 4.3 Medium
Missing Authorization vulnerability in WPdiscover Accordion Slider Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accordion Slider Gallery: from n/a through 2.7.
CVE-2025-13896 2 Wordpress, Wpdiscover 2 Wordpress, Social Feed Gallery Portfolio 2025-12-08 6.4 Medium
The Social Feed Gallery Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [igp-wp] shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-49325 1 Wpdiscover 1 Photo Gallery Builder 2024-10-22 4.3 Medium
Subscriber Broken Access Control in Photo Gallery Builder <= 3.0 versions.